Posted by Shahar Epstein on Sep 29 Severity: low Affected versions: - Apache Airflow Google provider before 22.6.0 Description: Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the...
CVE-2026-81914: Apache Airflow Google provider: Google Drive query injection via unescaped file and folder names
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/985
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.





